Vulnerabilities exploitable today
374,073in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,645
Distribution · last window
- Critical2,342
- High8,460
- Medium6,416
- Low712
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2019-12612—25.7%
——8——CVE-2025-60739—25.6%
——8——CVE-2022-31664—25.6%
——8——CVE-2026-598956.1 MED25.6%
——8Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks the result as already escaped without HTML-escaping the input, allowing untrusted className values used in a JSX class attribute during server-side rendering to break out of the attribute and inject arbitrary markup. This issue is fixed in version 4.12.27.67dCVE-2026-24969—25.6%
——8——CVE-2017-6271—25.6%
——8——CVE-2026-54814—25.6%
——8——CVE-2012-0110—25.6%
——8——CVE-2024-43433—25.6%
——8——CVE-2017-1418—25.6%
——8——CVE-2026-672926.5 MED25.6%
——8FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/core/gateway/websocket.c). The client's Pong reply reuses a fixed 1024-byte response stream whose length is not sealed to the actual received Ping payload, so a malicious gateway/WebSocket peer sending a non-empty Ping control frame causes the client to reply with an overlong Pong that discloses bytes beyond the received payload (the peer receives the masking key and can unmask the reply). A zero-length Ping reaches an assertion and terminates the client (denial of service).4dCVE-2020-23561—25.6%
——8——CVE-2024-41878—25.6%
——8——CVE-2022-43665—25.6%
——8——CVE-2025-4011—25.6%
——8——CVE-2024-13413—25.6%
——8——CVE-2024-39535—25.6%
——8——CVE-2021-0654—25.6%
——8——CVE-2020-11031—25.6%
——8——CVE-2024-45042—25.6%
——8——CVE-2025-61935—25.6%
——8——CVE-1999-1023—25.6%
——8——CVE-2026-599266.1 MED25.6%
——8Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/directives/admonition.py concatenates the Admonition directive :class: option into the HTML class attribute without escaping, allowing attribute injection and cross-site scripting even when HTMLRenderer escape mode is enabled. This issue is fixed in version 3.2.1.68dCVE-2021-425548.2 HIG25.6%
——8An issue was discovered in Insyde InsydeH2O with Kernel 5.0 before 05.08.42, Kernel 5.1 before 05.16.42, Kernel 5.2 before 05.26.42, Kernel 5.3 before 05.35.42, Kernel 5.4 before 05.42.51, and Kernel 5.5 before 05.50.51. An SMM memory corruption vulnerability in FvbServicesRuntimeDxe allows a possible attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.35dCVE-2025-633976.5 MED25.6%
——8Improper input validation in OneFlow v0.9.0 allows attackers to cause a segmentation fault via adding a Python sequence to the native code during broadcasting/type conversion.73dCVE-2024-12078—25.6%
——8——CVE-2020-0504—25.6%
——8——CVE-1999-0850—25.6%
——8——CVE-2024-43430—25.6%
——8——CVE-2010-0825—25.6%
——8——CVE-2024-10795—25.6%
——8——CVE-2026-32531—25.6%
——8——CVE-2025-14864—25.6%
——8——CVE-2026-538786.1 MED25.6%
——8An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16.
`DomainNameValidator` does not prohibit newlines in domain names (unless used via a form field, since `CharField` strips newlines). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because `HttpResponse` prohibits newlines in HTTP headers.
Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.
Django would like to thank Bence Nagy for reporting this issue.68dCVE-2022-1998—25.6%
——8——CVE-2026-32127—25.6%
——8——CVE-2024-33394—25.6%
——8——CVE-2026-35167—25.6%
——8——CVE-2024-11275—25.6%
——8——CVE-2007-5827—25.6%
——8——